Vulnerability Database

319,897

Total vulnerabilities in the database

CVE-2023-28755

A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.

CVSS v3:

  • Severity: Medium
  • Score: 5.3
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Software From Fixed in
ruby-lang / uri 0.12.0 0.12.0.x
ruby-lang / uri 0.10.1 0.10.1.x
ruby-lang / uri - 0.10.0.x
ruby-lang / uri 0.11.0 0.11.0.x
Ruby icon uri 0.12.0 0.12.0.x
Ruby icon uri 0.12.0 0.12.1
Ruby icon uri 0.11.0 0.11.0.x
Ruby icon uri 0.11.0 0.11.1
Ruby icon uri 0.10.1 0.10.1.x
Ruby icon uri 0.10.1 0.10.2
Ruby icon uri - 0.10.0.1
debian / debian_linux 10.0 10.0.x
fedoraproject / fedora 36 36.x
fedoraproject / fedora 37 37.x
fedoraproject / fedora 38 38.x